---
title: "Agents with the Web Security feature enabled"
slug: "agents-with-the-web-security-feature-enabled"
updated: 2026-04-07T09:08:35Z
published: 2026-04-07T09:08:35Z
canonical: "support.perimeter81.com/agents-with-the-web-security-feature-enabled"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.perimeter81.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Agents with the Web Security feature enabled

When macOS and Windows agents have the [Secure Web Gateway (SWG)](/v1/docs/secure-web-gateway) feature enabled, additional steps are required after installation and first user sign‑in. These steps allow the agent to configure the required network extension, proxy settings, and certificate trust settings for secure web access.

## **Windows**

****When SWG is enabled, the agent may require administrator approval to complete the installation of web security components.

1. Install the Check Point SASE Agent.
2. Sign in to the agent.
3. If prompted by Windows to approve additional components, click Allow or Yes.
4. If prompted for administrator credentials, enter the credentials to continue.   
Note:Local administrator permissions are required to complete the SWG installation.

If the installation does not complete successfully, sign out of the agent and sign in again to restart the setup process.****

## **MacOS**

Note:If you already downloaded and installed the Secure Web Gateway (SWG) root certificate, skip this procedure. For more information, see [Downloading the Secure Web Gateway (SWG) root Certificate](/v1/docs/swg-certificate).

1. Install the Check Point SASE Agent.
2. Sign in to the agent.   
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1771332269588.png)**"Check Point SASE" would like to use a new network extension** popup appears.****
3. Click **Open System Settings**.  
Alternatively, go to: **System Settings** → **General**→ **Login Items & Extensions** → **Network Extensions**.  
**![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1771332664811.png)**
4. In the **Network Extensions** section, enable the toggle for **Check Point SASE.app**.  
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1771332744314.png)
5. Click **Done**.  
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1771332850107.png)**“Check Point SASE" Would Like to Add Proxy Configurations**popup appears.
6. Click **Allow**.
7. When the system displays the certificate trust dialog, enter your macOS password.  
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1771332971401.png)
8. Click **Update Settings**.
9. The SWG setup process is complete.  
Note:If the SWG root certificate is already installed, the certificate approval prompt does not appear.

## Troubleshooting

### System Extension Installation Error

If the network extension was not approved during login:

1. Sign out of the Check Point SASE Agent.
2. Sign in again.

Complete the approval procedure when prompted.

### SWG Certificate Denied or Blocked

If the SWG certificate was denied, browsers display a certificate error when accessing websites.

![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1771333656095.png)

1. Open **Keychain Access** (Press **Cmd + Space**, then search for Keychain Access).
2. Locate the certificate named **Check Point SASE Secure Web Gateway 2**.
3. Right-click the certificate and select **Get****Info**.   
![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1771339111570.png)
4. Set trust permissions to **Always Trust.**  
**![](https://cdn.document360.io/44667c0c-50d7-412a-acbd-20d4a41c952e/Images/Documentation/image-1771339370579.png)**Refresh the web page. The site should load without certificate warnings.
